We had similar advise from a security firm, and sent a request to mendix for implementing the header. I don't think it is currently possible to add your own headers in mendix.
We have recently added the possibility to add customer headers in Cloud v4. See paragraph 4.2 of https://docs.mendix.com/developerportal/deploy/environments-details.
Tom de Groot
Product Manager Mendix Cloud